BIOC
Informational
✕
Modification of the Winlogon\Shell Registry key
Malware may modify the Winlogon\Shell Registry value to load itself instead of explorer.exe, which is the default system shell.
- Module:
- Platform Analytics
- Agent event type:
- Registry
- Category:
- Persistence
- Status:
- Enabled
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Boot or Logon Autostart Execution: Winlogon Helper DLL (T1547.004)
Indicator:
Registry registry data != explorer.exe AND registry key name = *\software\microsoft\windows nt\currentversion\winlogon* AND registry value name = shell AND action type = set_registry_value Host host os = windows
Preventable: yes